Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6v96-m24v-f58j

Опубликовано: 21 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 4.8
CVSS3: 3.1

Описание

CKEditor4 low-risk cross-site scripting (XSS) vulnerability linked to potential domain takeover

Affected Packages

The issue impacts only editor instances with enabled version notifications.

Please note that this feature is disabled by default in all CKEditor 4 LTS versions. Therefore, if you use CKEditor 4 LTS, it is highly unlikely that you are affected by this vulnerability. If you are unsure, please contact us.

Impact

A theoretical vulnerability has been identified in CKEditor 4.22 (and above). In a highly unlikely scenario where an attacker gains control over the https://cke4.ckeditor.com domain, they could potentially execute an attack on CKEditor 4 instances. Although the vulnerability is purely hypothetical, we have addressed it in CKEditor 4.25.0-lts to ensure compliance with security best practices.

Patches

The issue has been recognized and patched. The fix is available in version 4.25.0-lts.

For More Information

If you have any questions or comments about this advisory, please email us at security@cksource.com.

Пакеты

Наименование

ckeditor4

npm
Затронутые версииВерсия исправления

>= 4.22.0, < 4.25.0

4.25.0

EPSS

Процентиль: 19%
0.00061
Низкий

4.8 Medium

CVSS4

3.1 Low

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 3.1
ubuntu
больше 1 года назад

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability has been identified in CKEditor 4.22 (and above). In a highly unlikely scenario where an attacker gains control over the https://cke4.ckeditor.com domain, they could potentially execute an attack on CKEditor 4 instances. The issue impacts only editor instances with enabled version notifications. Please note that this feature is disabled by default in all CKEditor 4 LTS versions. Therefore, if you use CKEditor 4 LTS, it is highly unlikely that you are affected by this vulnerability. If you are unsure, please contact us. The fix is available in version 4.25.0-lts.

CVSS3: 3.1
nvd
больше 1 года назад

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability has been identified in CKEditor 4.22 (and above). In a highly unlikely scenario where an attacker gains control over the https://cke4.ckeditor.com domain, they could potentially execute an attack on CKEditor 4 instances. The issue impacts only editor instances with enabled version notifications. Please note that this feature is disabled by default in all CKEditor 4 LTS versions. Therefore, if you use CKEditor 4 LTS, it is highly unlikely that you are affected by this vulnerability. If you are unsure, please contact us. The fix is available in version 4.25.0-lts.

CVSS3: 3.1
debian
больше 1 года назад

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. ...

EPSS

Процентиль: 19%
0.00061
Низкий

4.8 Medium

CVSS4

3.1 Low

CVSS3

Дефекты

CWE-79